Information
The recommendation is to ensure that PrivacyOptions includes at least three settings:
- authwarnings (a default)
- novrfy
- noexpn
The sendmail deamon has a history of security vulnerabilities. The recommendation is to modify default sendmail settings that otherwise may provide information that can be used by an attacker.
- novrfy: No Verify: do not verify valid email addresses. This can be used by attackers, e.g., phishing attacks.
- noexpn: no expansion: do not verify/expand email list addresses - providing attackers with a list of valid email addresses.
Solution
Edit the /etc/mail/sendmail.cf file and add any missing options to the O PrivacyOptions directive.
Example
O PrivacyOptions=authwarnings noexpn novrfy
NOTE: sendmail.cf supports the use of both the comma and space characters to separate the options.